CVE · Critical

CVE-2025-13773 — Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13773 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 5.9.0 5.9.0 2025-12-23

CVE-2025-13773

The Print Invoice & Delivery Notes for WooCommerce plugin has a security flaw that allows unauthorized access to execute arbitrary commands on the server. This vulnerability exists due to an oversight in capability checks within the update function, combined with PHP being enabled in Dompdf and a missing escape character in the template file. As a result, attackers can exploit this weakness without needing authentication credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.